CVE Tools

Media Server

47 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Media Server, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.

Media Server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Media Server CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-010
2025-020
2025-030
2025-040
2025-050
2025-0611
2025-071
2025-081
2025-090
2025-100
2025-110
2025-120
2026-014
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-095

Severity

How the 47 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical49%
  • High2248%
  • Medium1941%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting Media Server.

  1. CVE-2026-96656Plex Media Server arbitrary file write7.2
  2. CVE-2026-96655Plex Media Server arbitrary-host SSRF4.3
  3. CVE-2026-96654Plex Media Server URL injection6.5
  4. CVE-2026-96652Plex Media Server SSRF4.3
  5. CVE-2026-96651Plex Media Server path traversal6.5
  6. CVE-2025-69417In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint.5.0
  7. CVE-2025-69416In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.5.0
  8. CVE-2025-69415In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.7.1
  9. CVE-2025-69414Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.8.5
  10. CVE-2025-34158Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and ...8.5
  11. CVE-2025-34101Serviio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO Parameter—
  12. CVE-2025-49198Poor quality of randomness in authorization tokens3.1
  13. CVE-2025-49197Deprecated TLS version supported6.5
  14. CVE-2025-49195No protection against brute-force attacks5.3
  15. CVE-2025-49194Unencrypted communication7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store